Bug 46188

Summary: linux: Multiple security issues (4.1)
Product: UCS Reporter: Arvid Requate <requate>
Component: Security updatesAssignee: Arvid Requate <requate>
Status: CLOSED FIXED QA Contact: Felix Botner <botner>
Severity: normal    
Priority: P2 CC: birkefeld, damrose, gohmann, hahn, honzzze, requate, scheinig, stoeckigt
Version: UCS 4.1   
Target Milestone: UCS 4.1-5-errata   
Hardware: Other   
OS: Linux   
URL: https://security.googleblog.com/2018/01/more-details-about-mitigations-for-cpu_4.html?m=1
What kind of report is it?: Security Issue What type of bug is this?: ---
Who will be affected by this bug?: --- How will those affected feel about the bug?: ---
User Pain: Enterprise Customer affected?: Yes
School Customer affected?: ISV affected?:
Waiting Support: Flags outvoted (downgraded) after PO Review:
Ticket number: 2018010521000309 Bug group (optional): Security
Max CVSS v3 score: 8.2 (CVSS:3.0/AV:A/AC:L/PR:N/UI:N/S:C/C:H/I:L/A:N)
Bug Depends on: 45243, 46029    
Bug Blocks:    

Description Arvid Requate univentionstaff 2018-01-30 10:27:26 CET
We should backport Kernel 4.9.78 to UCS 4.1-5

+++ This bug was initially created as a clone of Bug #46029 +++

* cpu: speculative execution bounds-check bypass (CVE-2017-5753)
* cpu: speculative execution branch target injection (CVE-2017-5715)CVE-2017-5715

Will probably require this:
- linux kernel update
- µcode update for Intel and AMD
- gcc update
- qemu update
- libvirtupdate

After that backport for UCS-4.1

+++ This bug was initially created as a clone of Bug #45981 +++
Comment 1 Arvid Requate univentionstaff 2018-01-30 10:59:37 CET
8e7c4cb: Advisories, copied from branch 4.2-3 and adjusted:

* linux.yaml
* univention-kernel-image-signed.yaml
* univention-kernel-image.yaml

Manual package update and reboot looked good:
* UCS 4.1-5 VM amd64
  > Spectre V2 mitigation: Mitigation: Full generic retpoline
* UCS 4.1-5 VM i386
  > Spectre V2 mitigation: Filling RSB on context switch
  > Spectre V2 mitigation: Mitigation: Full generic retpoline

Updated via univention-install univention-kernel-image
Comment 2 Felix Botner univentionstaff 2018-01-30 12:02:32 CET
OK - amd64/i386 (4.1-5 with ext updates)
OK - univention-install univention-kernel-image with 4.2-3 repo updates linux,
     univention-kernel-image and univention-kernel-image-signed
OK - reboot
OK - YAML files